Skip to content
AnthropicAnthropic

An initiative to secure the world's software | Project Glasswing

Project Glasswing is a new initiative that brings together Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks in an effort to secure the world’s most critical software. We formed Project Glasswing because of capabilities we’ve observed in a new frontier model trained by Anthropic that we believe could reshape cybersecurity. Claude Mythos Preview is a general-purpose, unreleased frontier model that reveals a stark fact: AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities. Read more: https://anthropic.com/glasswing

Apr 7, 20265mWatch on YouTube ↗

CHAPTERS

  1. 0:00 – 0:49

    Why rare software bugs can become worldwide security crises

    The video opens by framing how most people rarely notice software bugs—until a vulnerability causes severe, wide-reaching damage. Because modern software is deeply shared and reused, a single flaw can cascade across countless products and services.

    • Everyday users often don’t notice bugs because many are quickly fixed
    • Some vulnerabilities have severe, real-world consequences
    • Shared dependencies mean one bug can propagate globally
    • The scale of impact increases as software reuse increases
  2. 0:49 – 0:55

    The historical bottleneck: slow, expensive vulnerability discovery and patching

    It explains that traditional vulnerability hunting and remediation has been labor-intensive and costly. This creates a gap where serious issues can persist before they’re detected and fixed.

    • Security flaws have always existed in software
    • Finding vulnerabilities historically takes significant time and effort
    • Remediation can be expensive and slow
    • Delays increase the window of exposure
  3. 0:55 – 1:23

    LLMs raise the stakes for both attackers and defenders

    The narrative shifts to how advanced language models change cybersecurity dynamics. If models can write high-quality code, they can also help find—and potentially exploit—security vulnerabilities at a comparable level.

    • Code-capable LLMs can be used for security research
    • The same capabilities can benefit defenders or adversaries
    • Cybersecurity “bar” rises as models become more capable
    • Effective bug-finding can translate into effective exploitation
  4. 1:23 – 1:54

    Introducing Claude Mythos Preview and its unexpected cyber leap

    Anthropic describes a new model, Claude Mythos Preview, and notes it represents a significant jump in capability. Although not trained specifically for cybersecurity, improved coding ability carries over into stronger security performance.

    • Claude Mythos Preview shows notably improved cyber-relevant skills
    • Capability jump is described as a major step along an exponential curve
    • Model wasn’t trained directly for cyber, but for coding
    • Cyber performance emerges as a side effect of code competence
  5. 1:54 – 2:37

    From finding bugs to chaining exploits: autonomous, long-range attacker-like workflows

    The model’s strength is presented as reaching professional human levels for bug identification and going beyond by chaining multiple smaller vulnerabilities into sophisticated exploit paths. This long-horizon, autonomous task pursuit raises both defensive value and misuse risk.

    • Model performs comparably to professional humans at finding bugs
    • Can chain 3–5 vulnerabilities to create powerful exploit outcomes
    • Autonomy helps it pursue long, complex investigation paths
    • The same capability could cause harm if misused
  6. 2:37 – 2:56

    Why the model won’t be widely released—and why planning must start now

    Given the potential for misuse, Anthropic states the model will not be broadly released. The video underscores that stronger models are coming across the industry, making proactive defensive strategy urgent.

    • Powerful cyber-capable models pose real misuse risk
    • Decision: do not release this model widely
    • More powerful models will emerge from multiple actors
    • Need a concrete plan to respond to rising capabilities
  7. 2:56 – 3:30

    Project Glasswing: controlled partnerships to harden critical code

    Project Glasswing is introduced as a collaboration with organizations maintaining critical software. The goal is to place advanced tools with trusted defenders early, creating a collective head start in reducing systemic risk.

    • Launch of Project Glasswing to reduce ecosystem-wide risk
    • Partnering with stewards of critical, widely-used code
    • Early access for defenders creates a protective lead time
    • Focus on enabling faster discovery and remediation
  8. 3:30 – 3:36

    Early results: vulnerability discoveries across major platforms

    The partnership work has already surfaced vulnerabilities broadly, with researchers reporting dramatic increases in findings. The effort prioritizes high-impact foundational components like operating systems and widely deployed open source code.

    • Partners are finding vulnerabilities across many major platforms
    • AI-assisted work dramatically increases bug discovery rate
    • Open source scanning is a key initial focus
    • Operating systems prioritized due to internet-wide importance
  9. 3:36 – 4:27

    Concrete examples: decades-old OpenBSD issue and Linux privilege escalations

    Specific examples illustrate the real-world value: a long-standing OpenBSD crash bug and Linux vulnerabilities enabling privilege escalation from unprivileged user to administrator. Importantly, maintainers were notified and patches were deployed.

    • OpenBSD: 27-year-old bug enabling remote crash of servers
    • Linux: vulnerabilities enabling privilege escalation to admin
    • Responsible disclosure to maintainers
    • Patches deployed to protect downstream users
  10. 4:27 – 4:40

    Empowering maintainers: AI as an invaluable defensive tool

    The video emphasizes how valuable these capabilities are for maintainers who shoulder the burden of securing widely used software. Faster discovery and fixes can prevent exploitation before it occurs.

    • Maintainers need scalable help to secure critical code
    • Models can find vulnerabilities in first-party codebases
    • Earlier fixes reduce real-world exploitation risk
    • Defensive tooling can be transformative for under-resourced projects
  11. 4:40 – 5:11

    Coordinating with government and reframing cyber as societal security

    Anthropic describes engagement with U.S. government officials to evaluate risks and strengthen defenses. The message broadens: software underpins modern life, so cybersecurity is inseparable from societal security.

    • Outreach to U.S. government officials for collaboration
    • Assessing model risks alongside defensive opportunities
    • “Software ate the world”: digitization of daily life
    • Cybersecurity framed as security of society
  12. 5:11 – 5:48

    A long-term, cross-industry effort to make the world’s software safer

    The conclusion argues that no single organization can solve these challenges alone, and the work will take months to years. The stated aim is measurable: safer software, data, transactions, and critical infrastructure than before.

    • Need for broad industry cooperation and shared visibility
    • No single organization has the whole picture
    • Timeline is months to years, not weeks
    • Goal: reduce risk across software, data, finance, and infrastructure

Get more out of YouTube videos.

High quality summaries for YouTube videos. Accurate transcripts to search & find moments. Powered by ChatGPT & Claude AI.